MemCatalyst: Amplifying Data Auditing on Vision-Language Models via Data Poisoning

📅 2026-08-18
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出MemCatalyst,通过数据投毒方法增强视觉-语言模型的数据审计能力,以解决未经授权使用数据的问题。
📝 Abstract
Vision-Language models (VLMs) achieve outstanding performance largely due to the amount of training data available on the internet. At the same time, data holders (e.g., artists) urgently need to determine whether their data has been used for model training without authorization, which concerns both intellectual property rights and personal privacy. Data auditing, particularly through membership inference (MI), has attracted attention as a direct tool. This work proposes MemCatalyst, a set of data poisoning tools, aiming to amplify the data auditing performance on VLMs. MemCatalyst employs two strategies: Poisoning Text (PT) and Poisoning Image (PI). MemCatalyst forces VLMs to over-learn specific inconsistencies between image features and textual semantics during training, thereby increasing their susceptibility to membership information auditing. Crucially, the transferability of poisoned samples across different VLM architectures is demonstrated to be effective in the black-box setting. Extensive evaluations using five state-of-the-art data audits on two prominent VLMs demonstrate that MemCatalyst markedly enhances MI AUC scores with a minimal budget of poisoned samples, while maintaining a negligible impact on model performance.
Problem

Research questions and friction points this paper is trying to address.

Vision-Language Models
Data Auditing
Membership Inference
Intellectual Property Rights
Personal Privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Data Poisoning
Membership Inference
Vision-Language Models
🔎 Similar Papers
X
Xukun Luan
School of Computer Science and Technology, Beijing Institute of Technology
J
Jinyan Liu
School of Computer Science and Technology, Beijing Institute of Technology
Y
Yuhui Gong
School of Computer Science and Technology, Beijing Institute of Technology
Y
Yuanguo Bi
School of Computer Science and Engineering, Northeastern University; Engineering Research Center of Security Technology of Complex Network System, Ministry of Education
Bing Hu
Bing Hu
Unknown affiliation
Machine LearningData MiningStatistics
Xuesong Li
Xuesong Li
Beijing Institute of Technology
Di Wang
Di Wang
King Abdullah University of Science and Technology
Differential PrivacyMachine UnlearningKnowledge Editing